PT-2026-73159 · Scriban · Scriban

·

CVE-2026-74791

·

Published

2026-03-24

·

Updated

2026-08-17

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Scriban versions prior to 7.0.0
Description The software fails to clear the CachedTemplates dictionary when the TemplateContext.Reset() function is called, which allows cached templates to persist across reused contexts. This can be exploited through request-dependent ITemplateLoader implementations, enabling unauthorized access to template content from previous renders without re-triggering the TemplateLoader.Load() function.
Recommendations Update to version 7.0.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74791
GHSA-X6M9-38VM-2XHF

Affected Products

Scriban